VP, Cybersecurity Operations – Engineering
Job Description:
- Lead enterprise cybersecurity operations and engineering programs, including strategy, risk governance, roadmap development, budgeting, KPI reporting, and executive communications
- Contribute to cybersecurity policies, standards, procedures, and control frameworks
- Develop governance forums, steering committee materials, risk updates, and business cases for senior leadership
- Partner with legal, compliance, privacy, internal audit, technology, and business stakeholders
- Drive consistent security practices across corporate, cloud, application, and business environments
- Translate threat, control, and assessment findings into prioritized remediation plans
- Provide executive oversight for SOC/MSSP performance, alert monitoring, incident triage, escalation management, and operational readiness
- Own incident response planning, runbooks, tabletop exercises, and cross-functional response coordination
- Oversee threat intelligence, threat detection, threat hunting, and vulnerability management capabilities
- Ensure preparedness to protect, detect, respond to, and recover from cybersecurity events
- Develop and monitor operational metrics and service-level indicators
- Oversee cybersecurity technology and control capabilities across on-premises, cloud, endpoint, identity, and network domains
- Partner with infrastructure, platform, and software engineering teams to embed security into architecture and workflows
- Support secure development lifecycle, software assurance, secure coding, and application security initiatives
- Guide selection and optimization of SIEM, EDR, IDS/IPS, firewalls, vulnerability management, logging, monitoring, and protection technologies
- Promote automation, orchestration, and process simplification
- Lead cyber risk assessments across infrastructure, applications, vendors, business processes, and emerging technologies
- Support compliance and control maturity for NIST, ISO 27001, PCI-DSS, SOC, SOX, GDPR, privacy, and other requirements
- Provide security leadership for vendor reviews, architectural reviews, major initiatives, and transformation programs
- Build relationships with business and technology leaders to enable growth, resilience, and informed risk-taking
- Champion security awareness, education, and culture-building efforts
- Lead, coach, and develop cybersecurity managers and individual contributors
- Foster accountability, collaboration, continuous improvement, and service-oriented partnership
- Mentor technical teams on incident response, operational excellence, architecture, and executive communication
- Maintain the cyber risk register and risk governance process
- Support procurement calendar, budget, actuals, strategy documents, project portfolios, roadmaps, and C-suite/IT leadership materials
Requirements:
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent professional experience
- 12+ years of progressive cybersecurity experience, including leadership of enterprise security programs in complex, high-growth, or globally distributed organizations
- 7+ years of leadership experience managing managers, cross-functional teams, and/or external service providers across multiple cybersecurity domains
- Demonstrated success building or maturing cybersecurity governance, program management, security operations, and security engineering capabilities
- Strong working knowledge of cybersecurity frameworks, regulatory requirements, and assurance practices, including NIST CSF, ISO 27001, PCI-DSS, SOC, SOX, data privacy, and related standards
- Experience leading or overseeing incident response, threat intelligence, vulnerability management, detection engineering, and security monitoring programs
- Strong technical understanding of cloud security, identity and access management, endpoint protection, network security, logging and monitoring, system hardening, and enterprise security architecture
- Experience working closely with software development and infrastructure teams to integrate security into lifecycle management, architecture, and operational processes
- Proven ability to define metrics, communicate risk clearly, and present meaningful security insights to operational, technical, and executive stakeholders
- Strong business judgment and ability to balance risk reduction, operational efficiency, and strategic enablement
- Excellent written and verbal communication skills, with ability to influence across all levels of the organization
- Must be based in one of the listed remote locations: New York, Connecticut, California, New Jersey, Texas, or Ohio
Benefits:
- Short- and long-term incentives
- Growth and developmental opportunities
- Health care
- Retirement
- Vacation and other paid time off
- Additional offerings
- Reasonable accommodations for qualified individuals with disabilities